SPF, DKIM and DMARC Explained: The Complete Beginner’s Guide to Email Authentication
8 min read
If email from your domain lands in spam, or worse, strangers can send mail that looks like it comes from you, the cause is usually three missing DNS records. This guide explains what each one does, in the order you should set them up. You can check your current state at any point with our SPF, DKIM and DMARC Checker.
The problem: email has no built-in identity
The mail protocol was designed in a trusting era. The "from" address on a message is a claim, not a proof, and nothing in the original system stops a spammer typing your domain into that field. SPF, DKIM and DMARC are the three identity layers added since, and modern receivers, Google and Yahoo explicitly since 2024, expect all three.
SPF: the guest list
An SPF record is a DNS TXT record listing which servers may send mail for your domain. A receiving server checks the sending server against the list. Two traps matter. Every service you add (your mailbox provider, your invoicing app, your newsletter tool) costs a DNS lookup, and the standard caps the total at 10 lookups; go over and SPF fails entirely. And the ending matters: "-all" (hard fail) is the strong finish, "~all" (soft fail) the weaker one.
DKIM: the wax seal
DKIM signs each outgoing message with a private key, and publishes the matching public key in DNS under a name called a selector, chosen by your mail provider. Receivers verify the signature to prove the message was not altered in transit and really passed through an approved sender. Your job is only to switch it on in your provider's settings and publish the DNS record it gives you; our checker hunts through the common selectors, and your provider's settings page names yours if it is unusual.
DMARC: the instruction sheet
DMARC ties the two together and answers the question they leave open: what should a receiver do with mail that claims to be from you but fails? A record at _dmarc.yourdomain sets the policy: "none" (deliver it, but send me reports), "quarantine" (spam folder), or "reject" (refuse it). The reports are the quiet superpower here, they show you every service sending as your domain, legitimate or not.
The safe rollout order
First, SPF: list every real sender, and remove services you no longer use. Second, DKIM: enable it in each sending service and publish the keys. Third, DMARC at p=none with a reporting address, and watch the reports for a few weeks until nothing legitimate is failing. Then step up to quarantine, and finally reject. Skipping to reject on day one is how people block their own invoices.
How this connects to deliverability
Authentication is the floor, not the ceiling: a domain with perfect records can still hit spam with bad content or a dirty list, and a domain on a blacklist has a separate problem to fix (check with the Blacklist Checker). But without the three records, everything else you do for deliverability is built on sand.